Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add LiPu-jpg/Openwrite --skill oh-story-reviewgit clone --depth 1 https://github.com/LiPu-jpg/OpenwriteWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/lipu-jpg/openwrite/oh-story-review)<a href="https://agentmods.dev/skills/lipu-jpg/openwrite/oh-story-review"><img src="https://agentmods.dev/badge/skills/lipu-jpg/openwrite/oh-story-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/lipu-jpg/openwrite/oh-story-review"><img src="https://agentmods.dev/badge/skills/lipu-jpg/openwrite/oh-story-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 9 Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.Fix: Restrict tool access to only the tools required for the skill's stated purpose. Use an explicit allowlist rather than granting blanket access.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00076 | $0.00539 |
| Opus 5 | $0.00038 | $0.00269 |
| Sonnet 5 | $0.00015 | $0.00108 |
| Haiku 4.5 | $0.00008 | $0.00054 |
Grade B, and why
oh-story-review scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accessmediumExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
allow_tools: ["*"] What it actually says
Oh Story 商业审稿
先确认审查对象、范围、目标读者和用户要“只诊断”还是“诊断后给修改稿”。默认只输出审查报告,不直接改动正文。
执行流程
- 读取当前项目已确认资产、相关正文和审稿范围,先做缺失资料与冲突预检。
- 使用
references/method.md按阻断、严重、一般、润色四级检查,不让文风偏好掩盖事实或结构问题。 - 每条发现给出位置或引文、问题、读者影响、证据和最小修复方向;证据不足时标记“需补充”。
- 汇总最高优先级问题、可保留优点、建议修订顺序和仍需作者裁定的取舍。
- 只有用户明确要求修改时才生成候选稿;涉及正式正文提交时继续走 OpenWrite workflow。
OpenWrite 边界
- 以当前
src/和已提交正文为事实基线,不把审稿偏好写成新设定。 - 不执行上游多 Agent、脚本或自动改稿协议;使用 OpenWrite 现有 Reviewer 和当前工具权限。
- 不因检查 AI 味而机械删除词语;表达层问题可转交
@oh-story-deslop。
本 Skill 改编自 oh-story-claudecode 的 story-review,基于提交 48a4789d1f542eb672addf8ccb5dbdc20e63be46;MIT 许可见同目录 LICENSE。
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 36 lines · 76 tokens per session scan B 6625d490a3ac
oh-story-review is a skill published in the GitHub repository LiPu-jpg/Openwrite (715 stars, last pushed yesterday), licensed Apache-2.0. It adds 76 tokens to every session and 539 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it B with 1 finding (unrestricted tool access). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
awesome-novel
A nine-agent workflow for writing a novel with AI, from creating the initial setting through organizing the finished material. It can also bring an existing novel into the workflow.
audit-playbook
A code-security audit playbook covering source-code review, runtime checks, software dependencies, deployment settings, and AI-agent security risks.
ida-reversing
Perform reverse engineering and binary analysis in IDA Pro using natural language commands powered by IDA MCP. Use this skill whenever the user wants to: analyze executable files, understand function behavior, decompile code, explore cross-references, search for strings or bytes, patch binary code, document reverse…
workflow
A command set for starting and managing step-by-step automated workflows.
local-search
A local search component that finds web results using installed command-line tools and page parsers. It supports general web search and extra sources for areas such as Chinese pages, news, code questions, academic work, and reference material.
manage-taskboard
Manage work in the native DeepSeek Harness Taskboard with exact task ids and optimistic versions. Use when an Agent must inspect project work, claim an eligible todo, record progress or blockers, verify an implementation, submit it for human review, or release its own claim; also use when a human asks how to accept…